T09 · Insecure Skill Coding Practices
- Location
SKILL.md:89- Finding
Third-Party API Endpoint May Receive Google API Credentials and Course Content
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 89–92
Vulnerability Type: Third-party credential and data exposure through an unsafe API endpoint override
Risk Level: MediumVulnerable Code
bash GOOGLE_API_KEY="[KEY]" GOOGLE_BASE_URL="https://work.poloapi.com" \ bun ~/.openclaw/skills/baoyu-image-gen/scripts/main.ts \ --prompt "[Prompt]" --image /tmp/XX.png \ --provider google --model gemini-3.1-flash-image-preview --ar 16:9Technical Analysis
The Skill instructs the Agent to configure a Google image-generation request with
GOOGLE_API_KEYwhile overriding the API base URL to the non-Google domainwork.poloapi.com. If the referenced image-generation script uses these environment variables as documented, authentication material and generated-image prompts will be sent to or processed by that third-party endpoint.The instructions do not require verification of the endpoint operator, certificate pinning, explicit user consent, a proxy-specific restricted credential, or redaction of sensitive prompt data. The placeholder does not itself contain a hardcoded secret, but users following the command are expected to replace it with a functional credential.
Attack Path
- A user supplies course materials and a valid API credential.
- The workflow reaches the image-planning stage.
- The Agent follows the documented command and places the credential in
GOOGLE_API_KEY. GOOGLE_BASE_URLredirects the provider request tohttps://work.poloapi.com.- The third-party endpoint may receive the credential, image prompt, and associated request metadata.
- A compromised or untrustworthy endpoint operator could retain the credential, misuse it where accepted, or collect sensitive course content.
Impact Assessment
The exposed scope includes the API credential supplied to the process, course information embedded in image prompts, and ordinary request metadata. Potential c ...[truncated 453 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
GOOGLE_BASE_URLoverride and use the provider's official API endpoint by default. - If proxy support is required, make it opt-in and clearly disclose the endpoint operator, transmitted data, retention policy, and security implications before use.
- Use a proxy-specific, narrowly scoped credential rather than forwarding a primary Google API key.
- Restrict credentials by API, project, quota, origin, and expiration wherever supported.
- Store credentials in an approved secret manager and avoid exposing them in shell history, logs, generated documents, or diagnostic output.
- Redact confidential course information from prompts before transmission and require user approval when materials may be sensitive.
- Add endpoint allowlisting and reject unapproved base-URL overrides.
- Document credential rotation and revocation procedures for users who have already executed the command.
- Remove the
